Job Description
Job Description
Be Part of a High-Performing Team
Join a global financial services organization committed to maintaining resilient, secure, and highly regulated technology operations. The cybersecurity organization protects complex cloud and on-premises environments by strengthening monitoring, threat detection, and incident response capabilities.
This position supports a collaborative Security Operations team that works closely with SOC analysts, incident responders, threat intelligence specialists, security engineers, and technology partners. The environment is fast-paced and analytical, with a strong emphasis on measurable detection coverage, automation, operational excellence, and continuous improvement.
What’s In Store For You
- Engagement: W2 only; no C2C or 1099 arrangements.
- Hybrid position based in Charlotte, North Carolina.
- Opportunity to develop sophisticated threat detections across cloud and on-premises environments.
- Exposure to security analytics, detection-as-code, automation, MITRE ATT&CK, and modern security monitoring technologies.
- Collaboration with global cybersecurity, threat intelligence, incident response, and technology teams.
- Opportunity to directly improve the organization’s ability to identify and respond to emerging cyber threats.
How You Will Make an Impact
- Design, develop, test, tune, and maintain threat detection logic across cloud and on-premises environments.
- Improve alert quality, monitoring visibility, and the organization’s ability to detect and respond to malicious activity.
- Build and maintain log onboarding and data-ingestion processes for endpoint, network, identity, cloud, application, and infrastructure telemetry.
- Translate threat intelligence, attacker behaviors, and indicators of compromise into actionable monitoring use cases.
- Develop correlation rules, behavioral analytics, signatures, alert thresholds, and detection content that reduce false positives.
- Partner with SOC analysts and incident responders to investigate alerts, validate detection effectiveness, and identify coverage gaps.
- Map detection logic and security-monitoring coverage to the MITRE ATT&CK framework.
- Apply scripting, automation, and detection-as-code practices to improve testing, deployment, scalability, and lifecycle management.
- Evaluate security data sources, analytics capabilities, and monitoring technologies to identify opportunities for improvement.
- Maintain documentation covering detection logic, data sources, tuning decisions, operational procedures, and response playbooks.
- Ensure detection-engineering practices align with regulatory obligations, internal controls, and cybersecurity standards.
- Assess the effectiveness of monitoring controls and recommend practical improvements that strengthen cyber resilience.
Do You Bring Proven Success in Threat Detection and Security Analytics?
- At least 3 years of experience in detection engineering, SOC engineering, security analytics, cybersecurity operations, or a related discipline.
- Hands-on experience analyzing logs and telemetry from endpoint, network, identity, cloud, infrastructure, and application platforms.
- Experience working with SIEM, UEBA, EDR, SOAR, security data lakes, or comparable security-monitoring technologies.
- Strong knowledge of security query languages and data-analysis methods used to investigate events and build detection logic.
- Experience developing automation, scripts, detection-as-code pipelines, or repeatable security operations processes.
- Ability to convert threat intelligence, adversary behaviors, and attack techniques into practical detections.
- Experience mapping detections or security coverage to MITRE ATT&CK or a similar framework.
- Working knowledge of Windows, Linux, enterprise infrastructure, and cloud environments.
- Strong troubleshooting, analytical, and root-cause analysis capabilities.
- Ability to independently manage operational responsibilities and project deliverables.
- Clear written and verbal communication skills, including the ability to document technical detection logic and tuning decisions.
- Strong ownership, attention to detail, and the ability to collaborate effectively within a global team.
- Experience in incident response, threat intelligence, vulnerability management, security engineering, or cloud security is preferred.
